Question
What is a one-way function, and why is the word "impossible" in its definition not mathematically exact?
Answer
A one-way function is easy to compute in one direction (y = f(x)) but computationally infeasible to invert (finding x from y).
* Easy one way, practically impossible the other — a trapdoor (like RSA's prime factors) is the only shortcut back. *
The formal definition:
- Computing $y = f(x)$ is computationally easy (polynomial time)
- Computing $x = f^{-1}(y)$ is technically impossible — meaning it would take the best algorithms with massive resources over 100,000 years
The terms "easy" and "impossible" aren't mathematically rigorous — they're practical statements about computational effort. Mathematically, "easy" means polynomial time, and "impossible" means the inverse computation time grows exponentially per bit.
Tip: Think of a blender — turning fruit into a smoothie is easy, but reconstructing the original fruit from the smoothie is practically impossible.
Go deeper:
One-way function (Wikipedia) — the formal easy-to-compute / hard-to-invert definition and why their very existence is still an open problem (it would imply P ≠ NP).
Trapdoor function (Wikipedia) — the special case where a secret makes inversion easy, the engine behind RSA.
Note saved — thanks!
Question
What is a hash function in the most general sense, and what are the three types classified by security and key usage?
Answer
A hash function maps elements from a large (arbitrary-size) set to a small fixed-size set — like a funnel compressing data.
* Three families: a Type-1 checksum (no key, not secure), a Type-2 MAC (keyed, secure) and a Type-3 MDC (keyless, secure). *
Output sizes are typically: 128, 160, 224, 256, 384, or 512 bits.
The three types:
| Type | Key? | Crypto-Secure? | Name | Example |
|---|---|---|---|---|
| Type 1 | No | No | Checksum / check digit | ISBN, EAN, CRC |
| Type 2 | Yes | Yes | MAC (Message Authentication Code) | CBC-MAC, HMAC |
| Type 3 | No | Yes | MDC (Manipulation Detection Code) | SHA-2, SHA-3 |
Important naming note: MAC should really be called MIC (Message Integrity Code), since it provides integrity, not the full palette of authentication. The misnaming dates back to the 1970s when integrity and authenticity were conflated.
Go deeper:
Cryptographic hash function (Wikipedia) — properties, applications and the standard algorithm families.
Hashing Algorithms and Security (Computerphile) — an 11-minute intuition-builder for what a hash is and why it must be one-way.
Note saved — thanks!